skills/mukul975/anthropic-cybersecurity-skills/testing-for-xml-injection-vulnerabilities/Gen Agent Trust Hub
testing-for-xml-injection-vulnerabilities
Fail
Audited by Gen Agent Trust Hub on Mar 15, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides bash
curlcommands and a Python script using therequestslibrary to interact with and test XML-processing endpoints. - [DATA_EXFILTRATION]: Contains specific XML External Entity (XXE) payloads designed to retrieve sensitive data, such as
/etc/passwdor cloud provider metadata, from a user-specified target server. - [EXTERNAL_DOWNLOADS]: Documents and demonstrates the use of remote Document Type Definitions (DTDs) to facilitate blind XXE testing and data exfiltration.
- [SAFE]: The identified security-testing behaviors are consistent with the skill's primary purpose and are directed at target infrastructure defined by the user during authorized security assessments.
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata